Status: June 1, 2025

1. Responsible Party

SelectCode GmbH
Oskar-vonMiller-Straße 11
82008 Unterhaching
Germany

Contact:
Email: datenschutz@meingpt.com
Telephone: +49 89 54198646
Website: https://meingpt.com

Management: Florian Baader, Reiner Conrad

Data Protection Officer:
heyData GmbH
Schützenstr. 5
10117 Berlin
Email: datenschutz@heydata.eu

Competent Supervisory Authority:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach

2. Overview of Processing

This privacy policy informs you about the nature, scope and purpose of the processing of personal data when using our B2B AI platform meinGPT.

Important note for corporate customers: As an administrator, you are responsible for ensuring that data is used in accordance with data protection regulations within your organisation, particularly when processing employee data. A data protection impact assessment (DPIA) may be required.

Types of Data Processed

Data Subjects

The processing of personal data is based on the following legal bases:

4. Purposes of Data Processing

4.1 Provision of the meinGPT Platform

Processed data:

Purpose:

Legal basis: Art. 6(1)(b) GDPR (performance of a contract)

Storage period:

4.2 User Management and Authentication

Processed data:

Purpose:

Legal basis: Art. 6(1)(b) GDPR

Storage period:

4.3 Billing and Payment Processing

Processed data:

Purpose:

Legal basis:

Storage period: 10 years in accordance with § 147 AO and § 257 HGB

4.4 Employee Usage Analyses (B2B)

⚠️ ATTENTION Data protection risk: The processing of employee usage data is highly sensitive in terms of data protection law. Administrators must establish their own legal basis (e.g. works agreement) before activating these functions.

Processed data:

Purpose:

Legal basis:

Storage period:

Data protection guarantees:

5. Recipients and Categories of Recipients

5.1 AI Model Providers

Depending on the selected data protection level, your data will be transferred to the following categories of providers:

Level 1 - EU Only:

Level 2 - EU Hosting:

Level 3 - Worldwide with DPF:

Level 4 - Worldwide + PII Filter:

You can find the specific list of providers for your selected level in your data processing agreement (DPA).

5.2 Infrastructure Service Provider

Hetzner Online GmbH (hosting, Germany)

5.3 Other Service Providers

DPO note: Current data processing agreements must be in place for all of the following service providers. DPF certification must be checked for US providers.

Payment Processing

Stripe (USA/Ireland)

Support & Helpdesk

ProductLane GmbH (Germany) ✅

Forms & Surveys

Tally (Belgium) ✅

Webinars & Online Events

Microsoft Teams (USA/EU)

Integrations

Google Workspace (USA/EU)
Microsoft 365 (USA/EU)

6. Third Country Transfers

When using AI models outside the EU (Levels 3 and 4), data transfers to third countries are based on the following safeguards:

Despite protective measures, there is a residual risk with third country transfers, as the legal situation in third countries may differ from EU standards.

7. No Use for AI Training

Important guarantee: Your data will not be used by us or our processors for training AI models. This is contractually agreed with all providers.

8. Your Rights as a Data Subject

You have the following rights:

8.1 Right of Access (Art. 15 GDPR)

You can request information about your personal data processed by us.

8.2 Right to Rectification (Art. 16 GDPR)

You can request the rectification of inaccurate data or the completion of incomplete data.

8.3 Right to Erasure (Art. 17 GDPR)

You can request the erasure of your personal data ("right to be forgotten").

8.4 Right to Restriction of Processing (Art. 18 GDPR)

You can request the restriction of the processing of your data.

8.5 Data Portability (Art. 20 GDPR)

You have the right to receive your data in a structured, machine-readable format.

8.6 Right to Object (Art. 21 GDPR)

You may object to the processing of your data.

You may withdraw your consent at any time with effect for the future.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority.

How to exercise your rights:

9. Cookies and Tracking

We only use technically necessary cookies:

Session cookies: To maintain your login

Preference cookies: For your settings (language, theme)

No tracking cookies: We do not use any analysis or marketing cookies.

10. Storage Periods at a Glance

Administrator-Controlled Retention (B2B)

Full control for your organisation: As a B2B platform, we enable your administrators to set retention periods themselves in accordance with your company policies, compliance requirements and business needs.

Available Retention Options

Data TypeAdmin OptionsDefault (if not configured)Notes
Business Data
Chat histories & AI interactions30 days to unlimited12 monthsAdmin selectable by category
Uploaded documents30 days to unlimited12 monthsSeparate setting possible
Workflow data30 days to unlimited12 monthsDependent on business processes
Technical Data
API logs7-90 days30 daysFor debugging & billing
Security logs (IP addresses)7-180 days90 daysObserve compliance requirements
Not Configurable
Invoice data10 years (legal)-§ 147 AO, § 257 HGB
Contract data6 years after end-limitation periods
Account basic dataContract term + 30 days-recovery period

How Admin Control Works

Important for administrators: As an organisation, you are responsible for:

Our shared responsibility model:

Recommendations by Industry

IndustryRecommended Chat RetentionJustification
Financial services5–7 yearsRegulatory requirements (MiFID II, etc.)
Healthcare3–10 yearsPatient documentation, MDR
Public sector2-5 yearsArchiving obligations
Tech/software6-18 monthsProject cycles, support
Consulting2-5 yearsProject documentation

Additional Features

Note: Employees can request the deletion of their personal data at any time, provided that there are no legal retention obligations or legitimate business interests that prevent this.

Technical Implementation of Deletion

11. Data Security

We use extensive technical and organisational measures (TOMs):

Details can be found at: Technical and Organisational Measures

12. Newsletter and Marketing Communication

12.1 Newsletter Dispatch

Processed data:

Legal basis: Art. 6(1)(a) GDPR (consent)

Double opt-in:

Revocation: Each newsletter contains an unsubscribe link. Alternatively: Email to datenschutz@meingpt.com

Service provider: Loops (USA, standard contractual clauses)

12.2 Webinars

Processed data:

Legal basis:

Notes:

13. API Services

Special features for API users:

14. Protection of Minors

Our B2B services are aimed exclusively at companies and their adult employees. Use by persons under the age of 18 is not permitted.

15. Changes to the Privacy Policy

We reserve the right to amend this privacy policy. The current version can always be found on our website. We will inform you by email in the event of significant changes.

16. Contact

If you have any questions about data protection, please contact:

Data Protection Officer:
heyData GmbH
Schützenstr. 5
10117 Berlin
Email: datenschutz@heydata.eu